Noticed email about Sony year wrap out so decided to check what I played the most, clicked on that link, it opened the browser and to view the wrap out I had to login in, understandable. Entered the email address and then the 30+ long password with all the requested symbols, no biggie. They saying "looks like you trying to log in with a new device" like how did they knew that's exactly the same device I always log in to psn ? so they will send me an sms with pass code, cool. So I didn't receive any sms, no biggie I clicked to receive pass code to my email. They wrote they send me passcode to my email. So I opened my email and their was mail from Sony with no passcode, obviously but with information that someone from my location tries to enter my account and if it's not me to do something about it
Tldr: So path tracing dlsr mlrs petaflops AI decided that I am using new device so I can't now enter my account
Jump in the discussion.
No email address required.
Some sites will do this if your IP changes. And also use SMS instead of OTP. Those sites are written by H1Bs
Jump in the discussion.
No email address required.
SMS is weak to sim-swapping attacks and only works on your phone. OTP lets you own your own keys most of the time
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Jump in the discussion.
No email address required.
Websites, Banks, Healthcare orgs, etc. fricking LOVE to send SMS, they love paying the phone company to send a message like a sloppy little phoneslut
Jump in the discussion.
No email address required.
Honestly I think it's more that SMS 2FA is harder to "lose" for the average person. Most people don't change their phone number, but they do change their phone, and often don't bother to back up their data. So if you try and use OTP, then you'll run into situations where they no longer have access to the code. Whereas SMS will always just work so long as they have the same number.
Jump in the discussion.
No email address required.
Supporting only SMS is r-slurred tho
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
More options
Context
yeah we fricked up user authentication by having everyone handle it separately.
lots of basic processes are fricked up like that.
i hate how much of my life has been wasted on asinine complexity of our own creation
!codecels - just stop it already
Jump in the discussion.
No email address required.
one word: government issued virtual identity
Jump in the discussion.
No email address required.
how about intergovernmental id please...
like solve the darn problem once and for all u stupid !codecels
Jump in the discussion.
No email address required.
More options
Context
More options
Context
OIDC is ok
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
More options
Context
I miss web 1.0 when you didn't even need an email to register an account somewhere.
Jump in the discussion.
No email address required.
That's what makes this website to great
Jump in the discussion.
No email address required.
More options
Context
More options
Context
If you look up redditors complaining about their psn account being stolen, you will note that sony's IT is probably staffed wholly by laotian slaves for pennies a day
Jump in the discussion.
No email address required.
I am now getting email with passcode 10 minutes after I ask it to send to my email address. You get logged out in 90 seconds if you don't enter the passcode. Perfect. I could had understand if I was legit using new device or location. But Sony don't even remember my settings for more than 2 days
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Jump in the discussion.
No email address required.
More options
Context